CRISC IT Risk Identification Practice Question
A global manufacturer's risk committee is defining the organization's risk capacity and risk appetite for IT risk. The chief risk officer asks the practitioner to clarify how these two concepts relate. Which of the following statements is MOST accurate?
⚠ Common exam trap
The trap here is swapping the definitions so that capacity sounds like willingness and appetite sounds like ability, which inverts the entire governance hierarchy.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Risk capacity is the maximum risk the organization can bear, and risk appetite is the amount of risk it is willing to accept, with appetite normally set within capacity.
Risk capacity defines the outer limit of risk the organization can absorb, while risk appetite is the lower, deliberately chosen level of risk it is willing to accept to pursue objectives. Appetite is normally set within capacity so that a buffer remains for unexpected losses. This hierarchy lets the committee translate strategy into tolerances and limits, and it prevents risk-taking from silently approaching the point where the organization's viability is threatened.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Risk appetite applies only to financial risks, while risk capacity applies only to IT and operational risks.
Why it's wrong here
Both concepts apply across all risk categories, including IT risk, and are typically expressed at the enterprise level with supporting statements for each domain. Assigning appetite to financial risk alone and capacity to IT risk alone is artificial and would fragment the framework. The committee needs a coherent relationship between willingness and ability that spans the full risk landscape, not a split by category.
- ✗
Risk appetite is the maximum loss the organization can absorb, while risk capacity is the amount of risk management is willing to pursue for returns.
Why it's wrong here
This reverses the two definitions. Capacity is about the maximum risk the organization can bear given its resources and capital, while appetite is the amount of risk it is willing to accept in pursuit of objectives. Stating them backwards would cause the committee to set tolerance limits against the wrong benchmark and could lead to accepting exposure beyond what the organization can actually survive.
- ✓
Risk capacity is the maximum risk the organization can bear, and risk appetite is the amount of risk it is willing to accept, with appetite normally set within capacity.
Why this is correct
Capacity reflects the outer boundary of risk the organization can absorb before objectives or solvency are threatened, while appetite is the deliberate, lower level of risk it chooses to take. Setting appetite inside capacity leaves a buffer for unexpected events and keeps strategic risk-taking sustainable. This relationship is the foundation for deriving risk tolerances and limits that the committee can monitor.
- ✗
Risk capacity and risk appetite are interchangeable terms that both describe management's willingness to accept risk.
Why it's wrong here
Treating the terms as synonyms erases the distinction between what the organization can bear and what it chooses to bear. Capacity is a constraint derived from resources, capital, and resilience, whereas appetite is a deliberate choice shaped by strategy and stakeholder expectations. Collapsing them would remove the buffer that protects the organization when losses approach its true limits, undermining the governance purpose of the discussion.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CRISC question from scratch — 1,062 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.